Delegation intelligence from DNS-visible evidence, not marketing claims.
RootFetch computes structural movement in the global namespace from CZDS zone snapshots. It runs locally (no raw zone publishing), produces versioned model outputs (DVI + regime classification), and publishes immutable read-only artifacts for analysis, replay, alerting, and AI agents.
RootFetch is the verifiable structural layer, not a full threat-intelligence suite.
- Use RootFetch for immutable run evidence, replay/compare workflows, and agent-ready deterministic outputs.
- Use broad intel platforms for enrichment breadth and multi-signal threat context.
- Use both together when you need narrative speed plus citation-grade structural proof.
DVI_v1: bounded 0-100 volatility index (dispersion + concentration delta + anomaly clustering)Regime_v1: state machine with thresholds + hysteresis + minimum duration + confidence score- Immutable artifacts:
data/artifacts/runs/<run_id>/...withmanifest.json(size + sha256)
- Immutable run artifacts (cacheable for 1 year)
- Atomic
latest.jsonpointer (no mixed reads) - Auditable alert delivery (at-least-once + durable dedup + dead-letter)
- Static site on GitHub Pages: no servers, no hosting bill
.github/workflows/daily.ymlruns every day at 03:30 UTC on GitHub Actions (free for public repos): it fetches counts from CZDS, commits them underdata/, rebuilds the site withscripts/build_site.py, and deploys it to rootfetch.com on GitHub Pages.- The run fails, and GitHub emails the repo owner, when the newest data is more than 3 days old.
- Build the site locally with
python scripts/build_site.py(output in_site/). - Two ingestion modes:
- Day-1 baseline: ingest all approved CZDS TLDs in one resumable run.
- Daily hybrid (after baseline completion): core set daily + deterministic rolling long tail.
count_ns_sld: unique second-level owners with at least oneNSrecord.
This is a delegation footprint proxy, not total registrations.
- Never commit credentials/tokens/MFA seeds.
- Never commit
.envfiles. - Never commit raw zone files (
*.gz,*.zone,*.txt.gz). - Commit only safe aggregates under
data/and code/docs.
python -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"Set local env vars with a local credential file (.env.czds recommended; .env remains legacy-compatible):
CZDS_USERNAMECZDS_PASSWORD- optional
CZDS_TOTP_SECRET
Quick start:
cp .env.example .env.czds
chmod 600 .env.czds
rootfetch auth-checkOptional local MCP endpoint override for step-9 live checks (keep this local-only, never commit):
cat > .env.mcp <<'EOF'
ROOTFETCH_MCP_URL=https://rootfetch.com/mcp
EOF
chmod 600 .env.mcprootfetch auth-check
rootfetch discover
rootfetch run-baseline --dry-run
rootfetch run-baseline --resume
rootfetch baseline-status
rootfetch run-hybrid
rootfetch run-hybrid --dry-run
rootfetch compute-signals --date YYYY-MM-DD
python compute_model_v1.py snapshot.json
rootfetch rag build
rootfetch rag build-static
rootfetch rag search "count_ns_sld"
rootfetch mcp serve --transport stdio
rootfetch alerts run --date YYYY-MM-DD
rootfetch alerts run --date YYYY-MM-DD --recover-corrupt-state
rootfetch publish prepare --date YYYY-MM-DD --out-dir .ai/publish/latest
rootfetch publish run --source-dir .ai/publish/latest --artifacts-root data/artifacts --model-version rootfetch_model_v1 --snapshot-ts-utc 2026-02-25T23:15:01ZPrimary daily entrypoint:
./scripts/local_run_hybrid.shFull retest entrypoint (includes MCP checks when MCP URL is configured):
./scripts/retest_new_approvals.shBoth run scripts load local env files in this order: .env.czds -> .env -> .env.mcp.
The script auto-switches:
- runs
rootfetch discover - if baseline is incomplete, repeatedly runs
rootfetch run-baseline --resumeuntil 100% coverage - once baseline is complete, runs
rootfetch run-hybrid - rebuilds static RAG + commits safe artifacts only
See scheduler setups in docs/local_runner.md.
data/approved_tlds/latest.jsondata/daily_counts/<YYYY-MM-DD>.csvdata/growth_trends.csvdata/signals/*data/digests/*data/rag/rag_chunks.jsondata/rag/rag_meta.jsondata/artifacts/latest.jsondata/artifacts/replay/index.jsondata/artifacts/runs/<run_id>/*data/state/baseline_complete.json(written once baseline reaches 100%)
- Metrics: docs/metrics_spec.md
- Signals: docs/signal_spec.md
- Model contract v1: docs/model_contract_v1.md
- Artifact + caching contract: docs/caching_and_artifacts.md
- Operational guarantees: docs/operational_guarantees.md
- MCP server: docs/mcp_server.md
- MCP docs (public):
https://rootfetch.com/docs/mcp - MCP endpoint:
https://rootfetch.com/mcp - MCP live usage (public):
https://rootfetch.com/mcp/live - MCP hosting compatibility page:
https://rootfetch.com/docs/hosting/mcp/ - MCP glama connector:
https://rootfetch.com/.well-known/glama.json - Ops scoreboard: docs/ops_scoreboard.md
- Public positioning page:
https://rootfetch.com/for-teams - Team workflow runbooks:
https://rootfetch.com/for-teams/workflows - Integration runbooks:
https://rootfetch.com/docs/integrations - Operations scoreboard:
https://rootfetch.com/ops - Public endpoints: docs/public_endpoints.md
- Publishing checklist: docs/PUBLISHING.md
- GCP deployment: docs/gcp_deployment.md
- RAG: docs/rag.md
- CZDS credentials: docs/czds_credentials.md
- Local runner: docs/local_runner.md
RootFetch is a read-only intelligence layer. If it is not in the artifacts, it did not happen.
.github/workflows/rootfetch_daily.ymlruns scheduled ingestion and publish..github/workflows/release.ymlruns CI tests/build checks..github/workflows/gcp_deploy.ymldeploys web + telemetry services to GCP on safe artifact/code changes.